Legal

Cookie Policy

Last updated: September 14, 2026

This page explains what cookies and similar storage technologies the Mila by BPAUS website uses, what each one does, and how you can say no to the non-essential ones.

What is a cookie?

A cookie is a small text file that a website asks your browser to store on your device. The website can then read it back the next time you visit, which lets it remember small things between page loads — for example, that you have already dismissed the cookie banner.

We also use a related technology called localStorage, which is similar to a cookie but stored only on your device and never sent to our servers. Where we use localStorage in place of a cookie, we say so explicitly below.

Strictly necessary cookies

These are required for the site to work. You cannot turn them off through our banner — if you block them in your browser, parts of the site (most notably the checkout) will not function.

  • Session cookie (bpaus_mila_session): Tracks the current visit so the site knows which checkout form you are filling out and so the server can keep your form data together. Lifetime: until you close your browser.
  • CSRF token cookie (XSRF-TOKEN): Protects you from cross-site request forgery attacks during checkout. Required by our framework (Laravel). Lifetime: until you close your browser.
  • Cookie consent record (localStorage key mila_cookies): Stored on your device, not sent to our servers. Records whether you accepted or declined non-essential cookies, so we do not nag you on every visit. Lifetime: until you clear your browser storage.
  • Pending order draft (sessionStorage key mila_pending_order): Stored on your device only. Holds an in-progress checkout in case you accidentally close the modal, and is cleared automatically when the browser tab closes.

First-party campaign attribution

Set by our own site when you arrive, so that a sign-up or purchase can be matched to the campaign link that brought you here:

  • Campaign attribution (first-party cookie mila_attr, with a copy in sessionStorage under the same name): Holds the campaign parameters from the link you followed (utm_source, utm_medium, utm_campaign, utm_content, utm_term, and Meta's ad click identifier fbclid with the time of the click), plus the page you landed on and the site that referred you. It contains no name, email address or phone number, and is only sent to our server if you submit the free-trial or checkout form. Lifetime: 30 days (the sessionStorage copy is cleared when the tab closes).

Analytics and advertising cookies — optional

If you click Accept on our cookie banner, we may also set:

  • Google Analytics cookies (_ga, _gid, and similar): These tell us, in aggregate, how people use the site — which pages they read, which language they prefer, where they drop off in the checkout flow. We use this to make Mila better. We do not link this data to your name, email, or phone number. IP addresses are anonymized at the point of collection. Lifetime: up to 2 years for _ga, 24 hours for _gid.
  • Meta Pixel browser identifier (_fbp): Set by the Meta (Facebook and Instagram) Pixel to recognise your browser between visits, so Meta can tell us which of our ads led to visits and sign-ups. Lifetime: 90 days.
  • Meta ad click identifier (_fbc): Set by our site (or the Meta Pixel) when you arrived by clicking one of our Meta ads. It stores that click's identifier and time, so a sign-up can be credited to the ad. Lifetime: 90 days.

If you click Essential only, we do not set any analytics or advertising cookies, and we remove _fbc and _fbp if they were set during an earlier visit.

We advertise Mila on Meta. When you submit the free-trial or purchase form, our server also reports that sign-up to Meta and to Google Analytics, solely to measure the performance of our own advertising. Meta receives your email address and phone number in hashed (SHA-256) form, the ad-click identifiers _fbc and _fbp (only if you accepted cookies), and the IP address and browser user-agent of that request. Google Analytics receives anonymous, non-identifying event data — which event happened and which campaign it came from — with no name, email address, or phone number. Neither receives any information about your child, your screening answers, or your results. Details are in our Privacy Policy.

How to say no

You can decline non-essential cookies in three ways:

  • Click Essential only on the cookie banner the first time you visit.
  • Clear the mila_cookies entry from your browser's localStorage to bring the banner back, then decline.
  • Use your browser's built-in cookie controls. Every major browser (Chrome, Safari, Firefox, Edge) lets you block or delete cookies for a specific site or for all sites. The exact menu path differs by browser version — search "manage cookies in [your browser]" for current instructions.

Blocking cookies will not break the checkout: the strictly necessary cookies still work through your browser's session mechanism, regardless of whether you accept the optional ones.

Third-party cookies

Two third parties may set cookies on the Mila website itself, and only after you accept them through the banner: Google Analytics and Meta (through the Meta Pixel). We do not embed share buttons or other trackers that set cookies.

When you make a payment, you are redirected to Z-Credit or PayPal to enter card details. Those providers set their own cookies in their own domains, governed by their own cookie policies. We have no access to those cookies.

WhatsApp

The Mila screening conversation runs on WhatsApp, not in your browser. WhatsApp does not use browser cookies — it uses your phone number and the WhatsApp app's own internal storage. How WhatsApp (Meta) handles that data is governed by WhatsApp's own privacy policy, which is separate from ours.

Changes

If we add a new cookie or change how an existing one works in a way that affects you, we update this page and re-display the cookie banner so you can reconsider your choice.